CVE-2021-43314: Buffer Overflow
Published Mar 24, 2023
·Updated
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func getle32(). The problem is essentially caused in PackLinuxElf32::elflookup() at plxelf.cpp:5368
Affected Software
1 affected component
Upx Project Upx<4.0.0
Remediation
Patch Available
Event History
Mar 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the heap-based buffer overflow in upx?
The vulnerability ID for the heap-based buffer overflow in upx is CVE-2021-43314.
2
What is the severity of CVE-2021-43314?
CVE-2021-43314 has a severity rating of 7.5 (high).
3
Which software versions are affected by CVE-2021-43314?
All versions up to and excluding 4.0.0 of the Upx Project Upx software are affected by CVE-2021-43314.
4
How can I fix the heap-based buffer overflow vulnerability in upx?
To fix the vulnerability, update your Upx Project Upx software to version 4.0.0 or higher.
5
Where can I find more information about CVE-2021-43314?
You can find more information about CVE-2021-43314 at the following link: https://github.com/upx/upx/issues/380